Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Identity & Access Management
37 controls
13 services covered
Reviews direct identity and authorization controls, including Entra tenant settings, MFA, guest access, user consent, managed identity, Azure AD authentication, RBAC, local-auth disablement, and shared-key restrictions.
What we check
Entra Tenant Identity9
- Security Defaults are Enabled on Azure Active Directory
- Ensure self-service password reset is enabled
- Enable Conditional Access policies to block legacy authentication
- Admin Consent Workflow is Enabled
- Ensure 'Microsoft Azure Management' is limited to administrative roles
- Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users
- Enable Azure AD Identity Protection sign-in risk policies
- AD Account Provisioning Activity Report Reviewed
- Ensure the Azure AD 'Risky sign-ins' report is reviewed at least weekly
Guests and External Users6
- Ensure Guest Users are reviewed at least biweekly
- Ensure Guest Users are Reviewed Monthly
- Ensure Guest Invite Restrictions are Restricted
- Ensure Guest User Access Restrictions are Restricted
- Guest accounts with read permissions on Azure resources should be removed
- Guest accounts with write permissions on Azure resources should be removed
Entra MFA4
- Admin Users have MFA Enabled
- All Users have MFA Enabled
- Ensure Conditional Access MFA is Enabled
- Ensure MFA is Required for Device Join
User Consent and Groups4
- Ensure User Consent for Applications is Disabled
- Ensure User Consent is Limited to Verified Publishers and Selected Permissions
- Ensure Microsoft 365 Group Creation is Disabled
- Ensure third party integrated applications are not allowed
Event Grid Identity and Local Auth3
- EventGrid Domains Use Managed Identity
- EventGrid Topics Use Managed Identity
- EventGrid Topics Do Not Use Local Authentication
Managed Identity2
- Web Apps Should Use Managed Identity
- Function Apps Should Use Managed Identity
Storage Identity Authorization2
- Default to Microsoft Entra Authorization Should Be Enabled for Storage Accounts
- Shared Key Access Should Be Disabled for Storage Accounts
Cosmos DB Identity Authorization2
- Cosmos DB account 'Access Control' should be configured to use Azure Active Directory (AAD) and Role-Based Access Control (RBAC)
- CosmosDB Account Should Disable Key Based Metadata Write Access
Service Authentication1
- Service Bus Namespace should be configured with Azure Active Directory authentication
Search Identity1
- Search Services Use Managed Identity
Batch Identity1
- Batch Accounts Identity Provider Should Be Enabled
Container Instance Identity1
- Container Instance Container Groups Use Managed Identity
Cognitive Services Identity1
- Cognitive Services Accounts should have Local Authentication Methods Disabled
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
